Chinese Hackers Cyber Espionage Campaign Linked To Microsoft Exchange Servers Compromise At Least 30,000 U.S. Organizations
Thursday, March 18, 2021
Several hours later, the European Union body released a statement explaining that “no data extraction has been performed and we have no indication to think that the breach has gone beyond our email servers.”
“The exploitation of the 0days in question required some specific conditions (e.g. user account on the vulnerable system) and thus raises questions what exactly happened at EBA,” wonders Ilia Kolochenko, CEO at ImmuniWeb. “Another key question is when exactly EBA was compromised. If the intrusion had happened prior to the public disclosure of the vulnerability, it was just possible to do some system hardening and continuous monitoring for network anomalies – to prevent 0day exploitation – or at least to detect it in a timely manner.”
Kolochenko noted that EBA would hardly public agency affected by the cyber espionage campaign as more public authorities would discover being victims of exploitation through vulnerable Microsoft Exchange servers. Thus, he underscored the need for proper technical investigation before attributing an attack.
It’s also probable that the Chinese hackers will expand their attack vectors, while other threat actors will exploit the vulnerability to install backdoors for delivering malware and ransomware. Read Full Article
Infosecurity Magazine: Internet Crime Complaints Surge in 2020, Fueled By Pandemic